LOWVulnerability

CVE-2026-86194

Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call actions without authentication.

Properties

cve_id
CVE-2026-86194
signal_observed_at
2026-09-18T21:50:21+00:00
published_at
2026-09-05T13:18:14.727
last_modified
2026-09-18T18:17:18.397

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86194 — Ninja Signal Threat Intelligence | Ninja Signal